Audit log
Every action, who or what triggered it, and what happened to each person.
Why this exists. Changing someone's access is exactly the kind of event an auditor asks about six months later, usually on a day when nobody remembers doing it.
Jira → Apps → License Waste Manager → Audit LogIllustration
Audit Log
DashboardUsersAdmin RolesAPI TokensAutomationAudit LogSettings
| When | Action | Triggered by | Rule | Result | |
|---|---|---|---|---|---|
| 1 Aug 2026 03:00 | Remove from group | rule | Reclaim dormant Jira Software seats | 29 success 0 failed | View users |
| 24 Jul 2026 14:22 | Suspend user | manual | — | 3 success 1 failed | View users |
Affected users — 24 Jul 2026 14:22
| User | Account ID | Result | Error |
|---|---|---|---|
| Tomas Silva | 712020:d7a2… | success | — |
| External Auditor | 557058:0f00… | failed | User is managed by another organization |
What each entry records
- When it ran and what the action was — removed from group, added to group, revoked product access, suspended account, restored account.
- Triggered by: Manual, with the administrator's name and avatar, or Automated, with the rule's name. An action whose actor could not be resolved says Actor not recorded rather than guessing.
- Per-person outcome: account ID, display name, success, failure or skipped, and the reason text in either of the last two cases — including which protection list spared somebody.
- Counts of successes, failures and skips, so a partial run is obvious at a glance.
- The groups the action targeted.
Finding the entry you are looking for
- Search reaches every entry's summary, rule name and target groups, and the matched term is highlighted where it hit — each surviving row shows why it survived.
- Date: all, last 7 / 30 / 90 days, or a period with two dates.
- Actor: the administrators who actually appear in the log, plus Automated for entries nobody clicked.
- Status: Success, Partial — some people failed — or Failed.
- Action, Trigger and Rule narrow by what ran and what asked for it.
- The header counts both sides — 789 entries — showing 12 — so a narrow filter never reads as a small log, and Reset clears everything.
Show details expands one entry into its per-person rows: search for a person, filter by outcome — Changed, Failed or Skipped — and each name links to that account's page in admin.atlassian.com, so acting on what you find is one click.
Taking the evidence with you
- Export CSV writes the log under exactly the filters on screen — the file holds what you were looking at, no more and no less, with the same columns the table shows.
- Export these people (CSV), inside an expanded entry, writes that run's named people with each one's result and error — the attachment a licence-reduction ticket actually needs.
Entries are kept for 180 days, and there is no way to keep them longer
The audit trail is swept at the end of every scan: an entry older than 180 days is deleted, and so is its per-user detail, on the same horizon. That pairing is deliberate. An entry that outlived its detail would say “504 users affected” with no way left to see who they were — an audit trail decaying into a number. One horizon means a row is either fully answerable or gone.
Keep the evidence before it ages out
The audit entry is your proof that the seats you stopped paying for were released on a specific date. If a compliance review runs more than six months behind your clean-up, Export CSV the relevant entries somewhere outside the app while they are still there.